Skip to content

Privacy policy

LifeCloneAI Privacy Policy

Effective date: 1 September 2026

1. Who we are

LIFECLONEAI LTD is the controller for the personal data described in this policy. We are registered in England and Wales under company number 16337860. Our registered office is Flat 6 4 Waterhouse Lane, Kingswood, Tadworth, England, KT20 6EB.

Privacy contact: sales@lifecloneai.com

This policy explains how we use personal data when you visit lifecloneai.com, contact us, request or buy a service, receive permitted communications, or act as a supplier, adviser, or business contact.

If we process personal data solely on a Customer's documented instructions while delivering a service, the Customer may be the controller and we may be its processor. That processing may be governed by a separate data processing agreement and the Customer's own privacy information.

2. Personal data we collect

Depending on how you interact with us, we may collect:

  • Identity and contact data, such as name, role, organisation, email address, telephone number, postal address, and account identifiers.
  • Order and transaction data, such as services requested, order details, payment status, invoices, refunds, and purchase correspondence.
  • Payment information. Payment providers collect full payment-card details. We receive payment confirmation and limited transaction information needed to administer the order.
  • Communications and support data, including messages, meeting notes, form submissions, feedback, complaints, and support history.
  • Project and service data, including instructions, access records, configuration information, deliverables, and customer materials supplied for an agreed service.
  • Technical and usage data, such as IP address, device and browser information, timestamps, requested pages, referrer, security events, identifiers, and interaction data.
  • Marketing-preference data, such as subscription status, consent records, and opt-out requests.
  • Professional and business data, such as employer, business interests, public professional profile, and source of an introduction.
  • Compliance data, such as evidence needed to verify authority, prevent fraud, protect systems, manage disputes, or comply with law.

Do not provide special-category data, criminal-offence data, children's data, production credentials, or another person's confidential information through a general website form. Contact us first if an agreed service genuinely requires higher-risk data.

3. Where personal data comes from

We may obtain personal data directly from you, from your organisation or authorised colleagues, through our Shopify storefront and forms, from payment and service providers, from lawful referral partners, and from public professional or company sources relevant to a genuine business relationship.

If we obtain personal data from another source, we will provide privacy information when required and within the applicable period.

4. Why we use personal data

Purpose Typical data Lawful basis
Respond to enquiries and prepare a requested proposal Identity, contact, business context, communications Steps at your request before a contract; legitimate interests for business enquiries
Accept, administer, and deliver an order Identity, contact, order, transaction, project data Contract; legitimate interests where the contract is with your organisation
Process payments, refunds, invoices, and accounting records Identity, order, transaction, limited payment data Contract; legal obligation; legitimate interests in financial administration
Provide support and resolve complaints Identity, contact, communications, order, project data Contract; legal obligation; legitimate interests in support and dispute resolution
Secure the site and services, prevent abuse and fraud, and investigate incidents Technical, usage, account, compliance data Legitimate interests; legal obligation where applicable
Operate storefront, cart, checkout, account, and contact functions Technical, usage, order, account data Contract; legitimate interests; applicable storage and access exceptions
Measure and improve the website and services Technical, usage, feedback data Consent where required; otherwise legitimate interests where lawful
Send requested updates or permitted business marketing Identity, contact, preference, interaction data Consent where required; legitimate interests where permitted by law
Meet legal, tax, regulatory, and corporate obligations Identity, contact, transaction, compliance data Legal obligation
Establish, exercise, or defend legal claims Relevant records Legitimate interests; legal claims condition where applicable

Where we rely on legitimate interests, we consider the interest, necessity, and effect on people's rights and reasonable expectations. Where we rely on consent, you may withdraw it at any time without affecting processing that was lawful before withdrawal.

5. AI and automation

We may use approved AI-assisted tools to help draft, classify, summarise, analyse, or support work where appropriate safeguards and contractual permissions are in place.

We will not use confidential customer materials or personal data to train a general-purpose AI model unless the relevant controller has expressly authorised that use and it is lawful, transparent, and covered by the applicable contract and privacy information.

We do not use the public website to make solely automated decisions that produce legal or similarly significant effects. If this changes, we will provide the information and safeguards required by law before that processing begins.

6. Who we share personal data with

We may share personal data only where necessary and lawful with:

  • Shopify, which provides the storefront, forms, account, checkout, analytics, security, and related commerce infrastructure.
  • Payment providers presented during checkout.
  • Approved hosting, cloud, security, authentication, email, customer-support, file-storage, analytics, AI, automation, and professional-service providers used to run the business or deliver an agreed service.
  • Professional advisers, auditors, insurers, and financial institutions under appropriate duties.
  • A prospective buyer, investor, or successor in a genuine corporate transaction, with appropriate confidentiality and data-protection safeguards.
  • Courts, regulators, law enforcement, tax authorities, or other parties where required by law or reasonably necessary to protect legal rights.

We do not sell personal data for money. Shopify may process certain data as an independent controller for its own purposes. You can read the Shopify Consumer Privacy Policy and use the Shopify Privacy Portal.

7. International transfers

Some providers may process personal data outside the United Kingdom. Where a restricted transfer requires safeguards, we use an available lawful mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another valid safeguard. You may contact us for information about safeguards relevant to your data.

8. How long we keep personal data

We keep personal data only for as long as reasonably necessary for the purpose collected. In deciding the period, we consider the contract and service lifecycle, legal and tax obligations, limitation periods, the sensitivity and volume of the data, security needs, complaint and dispute handling, backup cycles, and whether the purpose can be achieved with anonymised data.

Customer materials processed for a service are returned or deleted as stated in the order or data processing agreement, subject to legal, security, and isolated backup-retention requirements. We retain a minimal suppression record where needed to respect a marketing opt-out.

9. Cookies and similar technologies

The site uses Shopify technologies and may use cookies, pixels, local storage, scripts, and similar storage or access technologies. Strictly necessary technologies support functions such as security, load balancing, forms, cart, checkout, session continuity, and privacy preferences.

Analytics and other non-essential technologies are used only where permitted by law. Where consent is required, Shopify's privacy preference tools may ask for and record your choice. You can reject or withdraw consent through the privacy controls made available on the site. Blocking some technologies may affect optional features but should not prevent strictly necessary functions.

For more information about Shopify technologies, see Shopify's Cookie Policy.

10. Marketing communications

We send electronic marketing only where permitted by applicable data protection and electronic-communications law. Marketing messages provide a clear way to opt out. Service, security, billing, and legal notices are not marketing and are limited to their operational purpose.

11. Security

We use organisational and technical measures intended to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, proportionate to risk. No internet service is completely secure. Do not send passwords, secret keys, full payment-card details, or high-risk data through ordinary email or general forms.

12. Your rights

Depending on the circumstances, UK data protection law may give you rights to be informed, access your data, correct inaccurate data, request deletion, restrict processing, receive certain data in a portable format, object to processing, withdraw consent, and obtain safeguards in relation to qualifying automated decision-making.

These rights are not absolute and exemptions may apply. To make a request, email sales@lifecloneai.com. We may need information to verify identity and authority. We will respond within the legally required period and explain any lawful refusal or extension.

13. Complaints

You may complain to us about how we handle personal data at sales@lifecloneai.com. We will acknowledge the complaint within 30 days, make appropriate enquiries, keep you informed, and tell you the outcome without undue delay.

You also have the right to complain to the Information Commissioner's Office. Current information is available at ico.org.uk. We would appreciate the opportunity to address the concern first, but you do not surrender any legal right to contact the ICO.

14. Children

The website and services are directed to businesses and adults and are not intended for children. We do not knowingly seek children's personal data through the public website. A service involving children's data requires a separate legal and risk assessment before processing begins.

15. Third-party sites

Links to third-party sites and services are provided for convenience. Their operators control their own processing and privacy information. This policy does not describe their independent activities.

16. Changes to this policy

We review this policy regularly and update it when our processing changes. We will state the effective date and bring material new uses of personal data to people's attention before they begin where required.